PT-2023-6051 · Linux+4 · Linux Kernel+4

Jürgen Groß

+1

·

Publicado

2023-10-09

·

Atualizado

2025-06-05

·

CVE-2023-34324

CVSS v2.0

6.1

Média

VetorAV:N/AC:L/Au:M/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of an event channel is triggered by removal of a paravirtual device on the other side, which can cause console messages to be issued on the other side quite often, making the chance of triggering the deadlock not neglectable. Note that 32-bit Arm-guests are not affected, as the 32-bit Linux kernel on Arm doesn't use queued-RW-locks, which are required to trigger the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06752
CVE-2023-34324
DLA-3710-1
DLA-3711-1
DSA-5594-1
MGASA-2023-0328
MGASA-2023-0331
OESA-2023-1779
OESA-2023-1780
OESA-2023-1781
OESA-2023-1782
OESA-2023-1783
OPENSUSE-SU-2023_4343-1
OPENSUSE-SU-2023_4345-1
OPENSUSE-SU-2023_4347-1
OPENSUSE-SU-2023_4348-1
OPENSUSE-SU-2023_4351-1
OPENSUSE-SU-2023_4375-1
OPENSUSE-SU-2023_4378-1
OPENSUSE-SU-2023_4414-1
SUSE-SU-2023:4343-1
SUSE-SU-2023:4345-1
SUSE-SU-2023:4346-1
SUSE-SU-2023:4347-1
SUSE-SU-2023:4348-1
SUSE-SU-2023:4349-1
SUSE-SU-2023:4351-1
SUSE-SU-2023:4358-1
SUSE-SU-2023:4359-1
SUSE-SU-2023:4375-1
SUSE-SU-2023:4377-1
SUSE-SU-2023:4378-1
SUSE-SU-2023:4414-1
USN-6461-1
USN-6624-1
USN-6625-1
USN-6625-2
USN-6625-3
USN-6626-1
USN-6626-2
USN-6626-3
USN-6628-1
USN-6628-2
USN-6652-1

Produtos afetados

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu